I am trying to parse, extract and filter messages based on certain values in the keyvalue output. However, the query does not return any results.
Sample message -
| replace(_raw, "?","") as _raw| replace(_raw, "&"," ") as _raw || keyvalue auto | where error="20"
I am able to see the extracted fields in the sidebar when I remove the where clause. Any suggestions on how to get this to work?
Please sign in to leave a comment.